feat: show dev dependency label in terminal and HTML report#604
Merged
Conversation
96bb349 to
32ef0ce
Compare
…ings in HTML report
…DevPackages to shared utils
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Surfaces whether a vulnerable package is a devDependency in terminal output and the HTML report, so developers can immediately distinguish build-time risk from runtime risk.
What changed
devDependenciesinpackage.json. npm, pnpm, and Bun already set this correctly.direct · devortransitive · devwhen the finding is from a devDependencydirect · devbadge for devDependency findingsserializeFindingnow includesdev: booleanin its outputBehaviour
A package is only labelled
devwhen every known dependency path to it starts from adevDependenciesroot. If a package is reachable from both prod and dev roots, no label is shown.Closes #578